Title :
Visualizing enterprise-wide security (VIEWS)
Author :
Brennan, J.J. ; Faatz, Don ; Rudell, Mindy ; Zimmerman, Carson
Author_Institution :
Mitre Corp., USA
Abstract :
This paper discusses VIEWS, a specification for building diagrams that describe the security features of systems. The authors´ recent experience with providing security architecture and engineering support to organizations with large, distributed applications suggests that security architecture and assurance efforts could benefit by following other engineering disciplines, where using graphical models is the norm. Security diagrams can help security architects understand a system ´s security posture and can assist them in detecting vulnerabilities. Additionally, diagrams facilitate communications about the security features of a design. The output of a modeling effort using VIEWS is a diagram depicting a system´s security features as well as those of the environment in which the system operates. A goal of VIEWS is to allow the display of important security features without injecting cluttering detail. This paper presents examples of security diagrams built with VIEWS.
Keywords :
data visualisation; distributed processing; formal specification; organisational aspects; security of data; graphical models; security diagrams; visualizing enterprise-wide security; Buildings; Communication system security; Computer security; Data security; Design engineering; Displays; Graphical models; Information security; Technology transfer; Visualization;
Conference_Titel :
Computer Security Applications Conference, 2004. 20th Annual
Print_ISBN :
0-7695-2252-1
DOI :
10.1109/CSAC.2004.49